Cybersecurity Fundamentals

iseeq Link

https://www.iseeq.lk/

Cybersecurity Glossary

Term Short Description
Cybersecurity Protecting systems, networks, and data from cyber threats.
CIA Triad Three core security principles.
Confidentiality Only authorized users can access data.
Integrity Data remains accurate and unaltered.
Availability Systems and data remain accessible when needed.
Authorization Grants permitted access to resources.
Authentication Verifies a user’s identity.
Digital Asset Valuable digital information or resource.
Vulnerability A weakness that can be exploited.
Threat Anything capable of causing harm.
Countermeasure (Control) A safeguard that reduces risk.
Brute Force Attack Tries every possible password.
Dictionary Attack Uses common password lists.
Credential Stuffing Uses leaked credentials on other sites.
Sniffing Capturing network traffic.
DoS / DDoS Flooding a service to make it unavailable.
Spoofing Faking an identity or address.
Phishing Fake messages to steal information.
Smishing Phishing using SMS messages.
Vishing Phishing through phone calls.
Social Engineering Manipulating people into revealing information.
Identity Theft Stealing someone’s personal identity.
Session Hijacking Taking over an active user session.
Keylogger Records keystrokes secretly.
Spyware / Adware Software that spies or shows unwanted ads.
Virus Malware that attaches to files.
Worm Malware that spreads automatically.
Trojan Malware disguised as legitimate software.
Ransomware Encrypts files and demands payment.
Rootkit Hides malicious activity on a system.
Zero-Day Exploit Exploits an unknown vulnerability.
SQL Injection Injects SQL commands into applications.
Hacker A person who tests or exploits systems.

Sri Lanka Cybersecurity & Legal Framework

**cert.gov.lk

SLCERT (Sri Lanka CERT)

Key Laws

Quick Summary

  1. SLCERT - National cyber incident response.
  2. Data Protection Act - Protects personal data.